Nigeria’s Banks and Fintechs Face Overlapping Data and Cloud Rules
Nigeria’s financial institutions and payment companies may have to meet both Central Bank and national cloud requirements as regulators establish overlapping rules for data storage, infrastructure...
Nigerian banks, fintechs and payment companies are facing overlapping regulatory requirements on data storage, cloud infrastructure and digital systems.
Table Of Content
On June 15, 2026, the Central Bank of Nigeria introduced rules requiring financial institutions and payment system participants to store and manage payment transaction data generated in Nigeria locally. The deadline for compliance is January 1, 2027.
Two months later, the Nigerian government unveiled the National Digital Cloud Policy, establishing a broader framework for cloud adoption, data classification, cybersecurity and digital infrastructure.
Different mandates, potentially concurrent obligations
The CBN framework focuses on payment transaction data, while the National Digital Cloud Policy takes a more graduated approach to government and regulated data. The overlap means businesses may need to assess both financial-sector rules and national technology requirements when designing their systems.
The regulatory landscape also includes the National Information Technology Development Agency and the Nigeria Data Protection Commission. NITDA has a broader role covering technology standards, cloud infrastructure and digital systems, while the data protection commission is relevant to personal data and cross-border transfers.
Awe described the relationship between the regulators as “a question of regulatory overlap” rather than a direct clash. The CBN’s mandate covers financial stability, payment systems and operational risk, allowing it to impose technology and cloud requirements on financial institutions. NITDA’s remit is broader and extends across national information technology and cloud policy.
The mandates do not automatically cancel one another out. A bank cannot disregard a CBN requirement because NITDA has a wider technology role, while CBN authority does not automatically displace NITDA requirements affecting supporting infrastructure.
Infrastructure and data decisions
Businesses may need to establish where production data, backups, disaster-recovery systems and security logs can be located. Cloud providers, meanwhile, must determine whether their infrastructure meets both national standards and financial-sector requirements.
Rahma Ibiyeye said there is “a legal boundary between the roles of the CBN and NITDA,” but added that the boundary does not mean only one regulator can oversee an arrangement involving cloud or data-centre services.
She gave the example of a bank using a data centre that meets NITDA standards while also demonstrating to the CBN that its payment data complies with financial-sector rules. Where both regimes validly apply, she described the obligation as “concurrent compliance” and said the business must comply with both.
Ibiyeye also distinguished between requiring financial institutions to use cloud infrastructure that meets specified standards and independently licensing or certifying cloud providers. The first falls within the CBN’s oversight of operational and technology risk, she said, while the second could move the central bank towards directly regulating technology providers.
Calls for clearer responsibilities
Adeoye Abodunrin argued that the agencies should have more clearly defined roles. Under his proposed arrangement, NITDA would lead on technical standards for cloud systems, data centres and digital infrastructure, while the CBN would apply those standards to banks and payment companies within the financial sector.
The differing scopes of the frameworks could allow a fintech, subject to other legal requirements, to keep core Nigerian payment data locally while using cross-border infrastructure for less sensitive workloads. However, several practical questions remain unresolved, including what qualifies as primary payment data, whether overseas backups are permitted and whether disaster-recovery systems must be located in Nigeria.
It is also unclear from the available information whether foreign providers could meet the requirements through a Nigerian availability zone or a local data-centre partner. For financial institutions and their technology suppliers, the January 1, 2027 deadline makes the interaction between the rules an immediate compliance issue.
No Comment! Be the first one.